Policy Document

Security Program Overview

Version 2026.3 · Updated February 8, 2026

Control baseline

DomainControl implementation
Identity and accessTenant-scoped bearer auth, role + scope checks, strict x-tenant-id binding
Webhook integrityHMAC-SHA256 signatures, idempotency replay ledger, exponential retry/backoff
AuditabilityImmutable audit events for policy updates, webhook actions, portability/deletion requests
Privacy by defaultNo PHI in telemetry or outbound notifications, redacted structured server logging

Related governance docs